Skip to content
View zpxlz's full-sized avatar

Block or report zpxlz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

ebpf

31 repositories

Process-aware, eBPF-based tcpdump

C 1,202 66 Updated Jan 16, 2026

Docker container for compiling static eBPF applications with libbpf-bootstrap

CMake 4 1 Updated Jul 17, 2024

Workshop: Forensic Analysis of eBPF based Linux Rootkits

C 13 2 Updated Mar 13, 2024

Kernel shell

C 11 3 Updated Mar 26, 2024

中国eBPF大会演讲题目和项目征集。

43 12 Updated May 15, 2025

Flow feature extraction tool built in Rust using eBPF

Rust 23 2 Updated Jun 21, 2025

Automated upstream mirror for libbpf stand-alone build.

C 2,642 479 Updated Feb 18, 2026

A Linux Host-based Intrusion Detection System based on eBPF.

C 457 86 Updated Dec 20, 2023

Get live information about applications that make network requests (based on eBPF)

C 54 8 Updated Sep 17, 2025

socketrace is an eBPF-based tool to trace kernel socket events. License Apache 2.0 and GPL-2.0

C 45 5 Updated Nov 7, 2024

bpflock - eBPF driven security for locking and auditing Linux machines

C 151 15 Updated Feb 16, 2022

eBPF UDP -> TCP obfuscator

C 275 20 Updated Nov 20, 2025

ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits

C 140 18 Updated Feb 28, 2023

LMP provides an eBPF Supermarket for developers, including eBPF tools, open-source projects based on eBPF, eBPF learning materials, Linux kernel learning materials, and more.

C 721 187 Updated Feb 11, 2026

eBPF distributed networking observability tool for Kubernetes

Go 3,099 273 Updated Feb 27, 2026

Linux eBPF backdoor over TCP. Spawn reverse shells, RCE, on prior privileged access. Less Honkin, More Tonkin.

C 1,663 184 Updated Oct 19, 2023

ebpf实现的端口复用程序

C 6 1 Updated Dec 1, 2024

利用eBPF进行端口复用,由BCC实现

Python 4 2 Updated Feb 19, 2024

A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

C 1,945 241 Updated Apr 7, 2024

Exploit tool implemented using ebpf.

C 210 29 Updated Jun 4, 2024

eBPF Observability - Distributed Tracing and Profiling

Go 3,731 421 Updated Mar 1, 2026

nysm is a stealth post-exploitation container.

C 267 38 Updated Jun 19, 2025

eBPF Port Knocking Tool

C 238 17 Updated Aug 23, 2023

ebpf-go is a pure-Go library to read, modify and load eBPF programs and attach them to various hooks in the Linux kernel.

Go 7,547 829 Updated Feb 23, 2026

vArmor-ebpf is a specialized project dedicated to maintaining the BPF code utilized by vArmor.

C 41 7 Updated Jan 26, 2026

eBPF Developer Tutorial: Learning eBPF Step by Step with Examples

C 3,958 563 Updated Feb 21, 2026

Various examples of using eBPF code

C 18 10 Updated Jan 3, 2024

Learning eBPF from zero to hero

38 6 Updated Dec 22, 2023

vArmor is a cloud native container sandbox system based on AppArmor/BPF/Seccomp. It also includes multiple built-in protection rules that are ready to use out of the box.

Go 442 48 Updated Feb 26, 2026

An eBPF🐝 Keylogger with C2-based RCE payload delivery

Rust 307 26 Updated May 12, 2025